Security utility
JWT Decoder
Decode a JWT header and payload without verifying its signature.
● This tool runs entirely in your browser. Your input is never uploaded to our servers.
Output
Your result will appear here…
How to use JWT Decoder
- Paste a JWT with three dot-separated segments.
- Select Decode to inspect its header and payload.
- Never treat decoded claims as verified until the signature is validated.
Example
Input:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c2VyLTEyMyIsImV4cCI6MTczNTY4OTYwMH0.signature
Output:
Header: {
"alg": "HS256",
"typ": "JWT"
}
Payload: {
"sub": "user-123",
"exp": 1735689600
}Use cases
- Inspect token claims during local development.
- Check a token's declared algorithm and type.
- Review token fields before implementing server validation.
About this tool
Decode a JWT header and payload without verifying its signature. Processing happens locally in your browser, so your input is not sent to a server or included in analytics.
Frequently asked questions
Does decoding verify the JWT signature?
No. Decoding only Base64URL-decodes the header and payload. It does not authenticate the token or validate claims.
Is the token sent to a server?
No. Decoding happens in your browser.
Should I paste a production access token?
Avoid exposing live credentials. Use a revoked or synthetic token for inspection.